Skip to content
Bpanda
English
Esc
↑↓navigate↵open⌘Jpreview
On this page

Checking User Synchronization with Entra ID

When the state of the users in Account Management does not match what you expect in Microsoft Entra ID: trigger a full synchronization and, while doing so, make visible which users still come from your tenant.

It may happen that the users and groups in Bpanda no longer match the state in your Microsoft Entra ID. This becomes noticeable in Account Management: the state there is different from what you expect after your changes in the tenant.

You can trigger the synchronization yourself — it runs in the provisioning of your Bpanda Enterprise App in Entra ID, and you do not need us for it.

Why this happens

The most common cause is an expired secret token. As long as it is not renewed, your changes from Entra ID no longer reach us. The longer this state persists, the greater the difference between the two states becomes.

A new token alone is not enough. With it, only the changes that arise from now on come through. Only a full synchronization catches up on the changes from the period in which the token was expired.

How to trigger the synchronization

You trigger the synchronization by assigning an additional attribute to all users in Entra ID. As soon as you save, the full synchronization begins. Afterwards you can tell from this attribute which users come from your tenant.

  1. In Entra ID, open your Bpanda Enterprise App and go to Provisioning under Manage.

  2. Click Edit provisioning.

  3. Expand Mappings and open Provision Microsoft Entra ID Users.

  4. Below the table of attributes, click Add New Mapping.

  5. Enter these values in the Edit Attribute dialog and confirm with Ok:

    Field Value
    Mapping type Constant
    Constant Value IsAlive
    Target attribute urn:ietf:params:scim:schemas:extension:enterprise:2.0:User:organization
    Match objects using this attribute No
    Apply this mapping Always
  6. Click Save. The confirmation prompt reports that all assigned users and groups will then be synchronized again — confirm with Yes.

Why the organization attribute? Only a few attributes are freely available in the SCIM schema. organization is one of them.

Important: Saving starts a full synchronization, not the usual cycle. Depending on the size of your directory, it will take a corresponding amount of time.

The attribute then remains on the users — until you remove the mapping again. This is not an oversight: it continues to show who comes from your tenant.

What happens next

What you see in Account Management depends on what had drifted apart:

  • Users who no longer exist in Entra ID appear under Marked for deletion.
  • Users who have been newly added only become available now — before, they did not exist for Bpanda.
  • Changed details of existing users are adopted by Bpanda for user name, first and last name, display name, title, organization, department, phone numbers and e-mail address. Language and profile picture are only adopted as long as they are still empty in Account Management. If a user has already set them themselves, they remain unchanged.

If something is still wrong afterwards

Between Entra ID and Account Management there is an intermediate station, Keycloak, which you cannot look into yourself. If the synchronization has run and the state still does not match, get in touch with us — we will check there.

For how synchronization works in normal operation and how long it takes, see Setting up Microsoft Entra ID.

Was this page helpful?